For many organisations, the operational cost of ransomware now extends well beyond system recovery — affecting customer trust, regulatory exposure, insurance claims, procurement relationships, and executive accountability.
Ransomware against South African organisations has shifted from broad opportunistic spray to deliberate, targeted extortion — usually exfiltrate-then-encrypt, with leak-site pressure layered on top. The defences that worked five years ago do not address the disclosure problem posed by leak sites. Effective ransomware protection in 2026 combines prevention controls, rapid detection, tested response, and regulatory readiness — operated as a continuous programme rather than a one-off project.
The short answer
Effective ransomware protection for South African companies rests on five disciplines: identity hardening, network segmentation, immutable and tested backups, 24/7 detection and response, and a rehearsed incident playbook that includes POPIA Section 22 notification readiness. Each layer addresses a different part of the modern exfiltrate-then-encrypt attack chain.
Hardened identity — most ransomware starts with a credential
Stolen, sprayed, or reused credentials are the leading initial-access vector for ransomware operators. Strong identity controls are the cheapest, highest-impact prevention investment available: phishing-resistant multi-factor authentication on every privileged and remote-access account, active monitoring for password compromise, regular review of dormant and over-privileged accounts, and elimination of Kerberoastable service accounts. Most environments fail this audit on first inspection.
Segment the network — make lateral movement expensive
Modern ransomware groups move laterally within minutes of initial access. Flat networks let them reach domain admin, backup infrastructure, and production systems quickly. Segmentation between user, server, backup, and OT zones — with deny-by-default rules and monitored east-west traffic — buys defenders the time they need to detect and contain before encryption begins.
Make backups immutable and test restoration
Backups remain the single highest-value control for recovery, but only when they are immutable (cannot be deleted or encrypted by an attacker who reaches them), offline or air-gapped where possible, and regularly restored. A backup that has never been tested at scale is a theory. Practical targets: monthly restoration tests of tier-1 systems, quarterly full disaster-recovery rehearsals.
Detect early — the dwell-time problem
Most ransomware incidents are visible in telemetry before encryption. Indicators include credential anomalies, reconnaissance tooling (BloodHound, ADRecon), command-and-control beaconing, and unusual archive activity. Managed detection and response, mapped to MITRE ATT&CK techniques relevant to ransomware operators (Initial Access, Discovery, Lateral Movement, Exfiltration, Impact), shortens dwell time from weeks to hours.
Rehearse the response — including POPIA notification
A ransomware response is a multi-team exercise: security, IT operations, legal, communications, executive, and, where applicable, the Information Regulator. Section 22 of POPIA requires notification of the Regulator and affected data subjects “as soon as reasonably possible” after a compromise that is likely to result in unauthorised access. Tabletop exercises that include the disclosure conversation surface coordination gaps before a real incident.
Preserve evidence — for insurance, law enforcement, and root cause
Recovery instincts and forensic preservation often conflict in the first hours of an incident. Forensic readiness — defined evidence-handling protocols, chain-of-custody procedures, and the right tooling to image before remediating — protects insurance claims, supports any law-enforcement engagement, and enables root-cause analysis that prevents recurrence.
Common ransomware weaknesses organisations still miss
- Shared administrator credentials
- unsegmented backup infrastructure
- untested recovery procedures
- unmanaged service accounts
- lack of incident coordination rehearsals, and incomplete asset visibility
Key Takeaways
- Most ransomware starts with a credential — identity hardening is the highest-impact prevention investment.
- Flat networks let attackers reach backups and production fast — segmentation buys detection time.
- Backups must be immutable, offline where possible, and regularly restored — untested backups are theoretical.
- Managed detection and response mapped to MITRE ATT&CK shortens dwell time from weeks to hours.
- POPIA Section 22 notification is part of the response playbook, not an afterthought.
- Forensic readiness protects insurance claims, law-enforcement engagement, and root-cause analysis.
How Cyber Resilience Can Help
Cyber Resilience helps organisations assess ransomware readiness across identity security, detection capability, backup resilience, forensic readiness, and POPIA-aligned response planning through structured technical and governance-led engagements.
Speak to our team to arrange a ransomware resilience scoping discussion.
